CIPP Cheat Sheet 2026
The 30 highest-yield CIPP facts, distilled from real exam questions. Print it, save it as a PDF, or study it here — free, no sign-up.
90 questions
150 min time limit
68.00% to pass
- Under the Gramm-Leach-Bliley Act (GLBA), what must financial institutions provide to customers at the time of establishing a customer relationship? → An initial privacy notice
- When must a CCPA-covered business provide a 'Do Not Sell or Share My Personal Information' opt-out link? → On its homepage if it sells or shares personal information
- Which federal agency has primary enforcement authority over national banks under GLBA's privacy provisions? → Office of the Comptroller of the Currency (OCC)
- The Fair and Accurate Credit Transactions Act (FACTA) most significantly amended FCRA by establishing: → The right to one free credit report per year from each major consumer reporting agency
- What right allows California consumers to correct inaccurate personal information held by a business? → Right to Correct (added by CPRA)
- Which type of entity is directly covered by HIPAA's Privacy Rule? → Covered entities (health plans, providers, clearinghouses)
- Under US law, what is the primary federal statute governing spam texts sent to mobile phones? → Telephone Consumer Protection Act (TCPA)
- Which privacy concern arises when employers use social media screening of job applicants? → Exposure to legally protected characteristics not visible during the interview process
- Under CCPA/CPRA, the right to correct inaccurate personal information must be fulfilled by a business within: → 45 days of receiving the request, extendable by another 45 days
- Under COPPA, what is the age threshold below which verifiable parental consent is required before collecting personal information? → 13
- Which US state law was the first comprehensive consumer privacy law passed in the United States? → California Consumer Privacy Act (CCPA)
- Under the Controlling the Assault of Non-Solicited Pornography And Marketing (CAN-SPAM) Act, which requirement applies to all commercial email messages? → A clear and conspicuous opt-out mechanism must be included
- Which technique renders data outside the scope of HIPAA by replacing direct identifiers with a code, provided a re-identification key is not disclosed? → Pseudonymization
- Which HIPAA right allows a patient to request that a covered entity not disclose their PHI to their health plan for services paid out-of-pocket? → Right to request restrictions on disclosures to health plans
- In the context of US employment privacy, which action by an employer is generally permissible without employee consent? → Recording calls on company phone systems after providing notice
- Which of the following constitutes a 'permissible purpose' for obtaining a consumer report under FCRA? → A credit transaction initiated by the consumer
- Which type of information was added to many states' breach notification laws following high-profile biometric data breaches? → Biometric data (fingerprints, facial recognition)
- Under the Privacy Act of 1974, which category of organization is directly regulated? → Federal government agencies maintaining systems of records
- Which of the following is NOT a permitted use or disclosure of PHI under the HIPAA Privacy Rule without patient authorization? → Marketing campaigns selling health products
- Under GLBA, which entities qualify as 'financial institutions' subject to its privacy provisions? → Businesses significantly engaged in financial activities
- The FCRA 'Furnisher Rule' primarily requires entities that report information to consumer reporting agencies to: → Maintain reasonable policies to ensure accuracy and integrity of reported information
- Under the CAN-SPAM Act, commercial email senders must: → Honor opt-out requests within 10 business days and include a physical postal address
- Under FERPA, when does a student's (not parent's) right to control education records begin? → When the student turns 18 or attends a postsecondary institution
- Which concept describes the practice of ensuring that data collected is adequate, relevant, and limited to what is necessary for the specified purpose? → Data minimization
- Which GLBA exception permits financial institutions to share NPI with unaffiliated third parties without offering consumers an opt-out right? → Joint marketing agreement exception
- A consumer contacts a credit bureau to dispute an inaccurate item. Under the FCRA, how long does the bureau generally have to investigate the dispute? → 30 days
- Under the 2023 FTC Safeguards Rule amendment, non-banking financial institutions must notify the FTC of breaches affecting how many customers? → 500 or more customers
- What is the primary purpose of a 'risk of harm' threshold in breach notification laws? → To require notification only when there is meaningful risk of harm to individuals
- What is the HIPAA Privacy Rule's general rule on the use of PHI for marketing? → PHI cannot be used for marketing without written patient authorization
- Which type of employee data is most commonly regulated by state biometric privacy laws like Illinois BIPA? → Fingerprint scans used for timekeeping or access control
Turn these facts into recall:
Was this helpful?